Soon i'll be performing an pentest on a webapplication that has been build using the Zend framework.Are there any suggestions what I should look for besides the normal web vulnerabilities? So anything in particular related to the Zend framework?

Along with what Jamie.R suggested, try to do a completely "default" installation, where you don't alter settings to improve security. Look for misconfigurations that could lead to various types of bugs as described in e.g., the owasp top 10 or whatever you prefer For many years, cPanel had a few misconfigurations that lead to e.g., dns zone transfers, etc.

I'm not sure how much this will help . but in to knowledge Zend Core Framework is pretty secured, once I did a pentest on a Zend . their was not much exploit . but I found some XSS , and Redirection flows and miss functions in vote poll . all because of poor verification on submitions

nytfox wrote:I'm not sure how much this will help . but in to knowledge Zend Core Framework is pretty secured, once I did a pentest on a Zend . their was not much exploit . but I found some XSS , and Redirection flows and miss functions in vote poll . all because of poor verification on submitions

@nytfox Ahh great thanks mate that is just the stuff I was looking for!

@Jamie.R and @MaXe Thanks for your advice, but your advice is more applicable to PHP in general. OWASP Top 10 and default installation failures are pretty common in the default PHP install. But I am really looking for issues that Zend framework based apps have. Still thanks for your comment though!